Repository navigation
Save auth login profiles with the account's primary (SPOG) URL - #6854
Open
Peter-Feng-32 wants to merge 2 commits into
Open
Peter-Feng-32 wants to merge 2 commits into
Peter-Feng-32 wants to merge 2 commits into
Conversation
Peter-Feng-32
force-pushed
the
spog-login-poll
branch
from
September 28, 2026 06:04
726dd30 to
3897e85
Compare
Collaborator
Integration test reportCommit: 3dea8ed
Top 6 slowest tests (at least 2 minutes):
|
`auth login --host <spog>` with a workspace (`?o=<id>` or `--workspace-id`)
now gets a workspace-scoped token: the profile saves
discovery_url=<spog>/oidc/.well-known/oauth-authorization-server?o=<id>, so
login and refresh use the workspace's own OIDC while API calls go to the SPOG
host. This also makes `--resource` work on SPOG hosts. Without a workspace the
login stays account-level, and a host passed with --host is saved as given.
In the login.databricks.com flow, picking an account saves the account's
primary URL (/api/2.0/accounts/{id}/provisioned-urls/primary), and picking a
workspace saves a workspace-scoped SPOG profile when the workspace's
/.well-known/databricks-config?include_primary_url=true returns a unified
primary URL that serves its OAuth.
auth token, logout, auth profiles and re-login hints handle the new profile
type; host-only token requests without a workspace ID stay account-level.
Co-authored-by: Isaac <no-reply@databricks.com>
Peter-Feng-32
force-pushed
the
spog-login-poll
branch
from
October 9, 2026 01:02
4a47e78 to
ff94699
Compare
…e host Drop the workspace-scoped SPOG profile type: SPOG profiles keep the account-level token they get today, which older CLIs, SDKs that only pass --host, and account APIs all work with. - login.databricks.com: picking a workspace whose account has a primary (SPOG) URL runs a second, account-level login through it. If that login fails or is cancelled, the workspace profile is saved as before. - --resource on a SPOG host with a workspace (?o= or --workspace-id) logs in at the workspace's own host, read from the SPOG host's ?o= OAuth metadata, because resource indicators are only honored on workspace-level authorize. Without a workspace, or if the host can't be found, login fails before opening the browser. Co-authored-by: Isaac <no-reply@databricks.com>
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
databricks auth loginsaves the account's primary (SPOG) URL in the login.databricks.com flow. SPOG profiles keep the account-level token they get today.GET /api/2.0/accounts/{account_id}/provisioned-urls/primaryand save the profile with that URL./.well-known/databricks-config?include_primary_url=truereturns a unifiedprimary_url, run a second, account-level login through it and save a SPOG profile (account_id+workspace_id). If that login fails or is cancelled, the workspace profile is saved as before. The browser only asks to sign in again when there's no session on the SPOG host.--resourceon a SPOG host: resource indicators are only honored on workspace-level authorize, so with a workspace (?o=<id>or--workspace-id) the login runs at the workspace's own host, read from the SPOG host's?o=OAuth metadata. Without a workspace, or if that host can't be found, login fails before opening the browser instead of silently ignoring the resource.A host passed with
--hostis otherwise used as given. Lookups are best-effort; the workspaceprimary_urlis only returned when the server flagdatabricks.login.enableDatabricksConfigDiscoveryPrimaryUrlis enabled.Testing
Unit tests for the lookups (including 404 as "no primary URL"), the account and workspace picks (second login, its options, and the fallbacks), the primary-URL switch, and
--resourcerouting.go test ./cmd/auth/... ./cmd/root/... ./libs/auth/... ./libs/databrickscfg/...and the auth acceptance tests pass. On staging, a SPOG--resourcelogin was routed to the workspace's own host.This pull request and its description were written by Isaac.